PT-2002-1571 · Asp Nuke · Asp-Nuke

Publicado

2002-06-11

·

Atualizado

2008-09-05

·

CVE-2002-0521

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ASP-Nuke versions prior to RC2
Description The issue allows remote attackers to execute script or gain privileges as other ASP-Nuke users. This can be achieved via script in the name parameter in "downloads.asp", the message parameter in "Post.asp", or a web site URL in "profile.asp".
Recommendations For ASP-Nuke versions prior to RC2, consider disabling the affected parameters, such as name in "downloads.asp", message in "Post.asp", to minimize the risk of exploitation until a fix is available. Restrict access to "profile.asp" to prevent attackers from using a malicious web site URL.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0521

Produtos afetados

Asp-Nuke